Get a Pentest and security assessment of your IT network.

News

Facebook paid $25,000 for CSRF exploit that leads to Account Takeover

Facebook paid a $25,000 bounty for a critical cross-site request forgery (CSRF) vulnerability that could have been exploited to hijack accounts simply by tricking users into clicking on a link. The flaw resides in the facebook.com/comet/dialog_DONOTUSE/. The hacker leveraged it to bypass CSRF protections and act on users behalf. The vulnerability could have also been exploited even to delete the account of a targeted user, but in this case, victims have to provide their password before account is deleted.”]

Source: https://securityaffairs.co/wordpress/81219/hacking/facebook-csrf-flaw.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Take note, next week update Adobe Reader and Acrobat to fix critical flaws

News

Linux bug leaves 1.4 billion Android users vulnerable to hijacking attacks